News

Security Experts Say That USB Security is Fundamentally Broken

The common USB stick has become the most common way of sharing and storing files on-the-go. With this in mind, a variety of malware and viruses were created in an attempt to take control of computers who do not have any security measures installed, such as antivirus software. Other means of ‘cleaning’ an USB drive would be to format its content, leading to every file being deleted along with any malware and virus program that might be present on the drive.

However, two security researchers state that security problems with USB drives run deeper than expected. They state that the “risk isn’t just in what they carry, it’s built into the core of how they work.” This is why security researchers Karsten Nohl and Jakob Lell plan to present a proof-of-concept malicious software by the name of BadUSB which is stated to highlight that USB devices have long been fundamentally broken.

BadUSB can be installed on a USB device to completely take over a PC silently, alter files and even redirect the user’s internet traffic. The malware is said to be installed on the flash drive’s firmware and not the memory, which means that the code can remain hidden long after the flash memory has been erased. Also, the researchers state that there is no easy fix for the vulnerability. They say that the USB stick needs to be blocked from sharing its content with the system or, plainly said, the USB drive needs to be physically removed to stop the infection.

“You can give it to your IT security people, they scan it, delete some files, and give it back to you telling you it’s ‘clean,’” says Nohl. But unless the IT guy has the reverse engineering skills to find and analyze that firmware, “the cleaning process doesn’t even touch the files we’re talking about.”

It is said that the vulnerability is not limited to USB drives. All sort of USB devices, spanning from keyboards to smartphones and even cameras can have their firmware reprogrammed with the malware in question. The researchers have stated that they used the BadUSB program on an Android device, having a “grab bag of evil tricks” happening as a result. Nohl and Lell tell that it replaced software being installed with a corrupted or backdoored version and even impersonated a USB keyboard that suddenly started typing commands.

The researchers tell that the infection can travel both from a computer to the USB and the other way around. Matt Blaze, a computer science professor from the University of Pennsylvania, is also aware of the shallow security veil that USB drives present. He also speculates that the NSA could have made a common practice out of infecting USB devices using this approach.

Matt points to a spying device by the name of ‘Cottonmouth’, which has been revealed in one of Edward Snowden’s leaks. The device, which hid in a USB peripheral plug, was advertised in a collection of NSA internal documents as surreptitiously installing malware on a target’s machine. However, the exact mechanism for that USB attack wasn’t described.

Thank you Wired for providing us with this information
Image courtesy of Wired

Gabriel Roşu

Disqus Comments Loading...

Recent Posts

Refract Gaming Crimson – Home & Casual Pre-Built Gaming PC

Pre-built gaming PC for casual and entry-level gaming Cherry-picked hardware and hand-built by Overclockers UK’s…

4 hours ago

MSI NVIDIA GeForce GT 1030 LP OC 2048MB DDR4 PCI-Express Graphics Card

One of the deciding factors in performance is the quality of the components used. That…

4 hours ago

LG 27″ Ultragear 27GS60F-B 1920×1080 IPS 180Hz 1ms Widescreen Gaming Monitor

We have raised UltraGear's speed standard from 144Hz to 180Hz. You can enjoy ultra-clear and…

4 hours ago

Cooler Master Mobius 140P ARGB High Performance Fan

Cooler Master’s Mobius 140P ARGB is our new series of performance fans. With our enhanced…

4 hours ago

Ducky Mecha Mini 60% RGB USB Mechanical Gaming Keyboard

MINIATURE DESIGNFull aluminum casing Durable exceptional reliable performance USB HID with the highest frequency of…

4 hours ago

MSI 32″ MAG 32C6X 1920×1080 VA 250Hz 1ms A-Sync Curved Gaming Monitor

Visualize your victory with the MSI MAG 32C6X gaming monitor. Equipped with a 1920x1080, 250Hz(OC)…

4 hours ago